The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1 as used in Python PyXML w3c-libwww and other software allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read a different vulnerability than CVE-2009-2625.
The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets which facilitates phishing attacks.
- CentOS Linux 4
- Oracle Linux 4
- Red Hat Enterprise Linux 4